XOpsセキュリティ検出レポートの生成

Prev Next

この記事では、CatoXOpsセキュリティ検出レポートの生成方法を説明し、アカウントのために作成されたXOpsストーリーを強調します。 また、アカウントの全体的なセキュリティ体制に関する洞察を提供します。

注: XOps は Cato のセキュリティおよび運用のための統一されたアナリティクス層であり、インサイトおよびガイド付きの是正措置を提供します。 XOpsはXDRを置き換えました。詳細については、XOps FAQをご覧ください。

概要

Catoは、アカウントに対して検出された全てのXOps (かつてのXDR)セキュリティストーリーのデータを要約する定義済みレポートテンプレートを提供します。 これにより、組織の関連する関係者に対してCatoXOpsの包括的な脅威検出能力を強調するレポートを生成できます。 XOps検出レポートには、作成されたセキュリティストーリーの総数、重大度別の内訳、XOpsストーリーにおける最も一般的なサイトと攻撃の兆候などのデータが含まれています。

定期または一回のレポート用テンプレートを作成し、レポートの期間を定義します。 デフォルトでは、XOps検出レポートのための定義済みレポートテンプレートは、過去週のストーリーデータを表示します。

レポートの利用方法について詳しくは、Cato Reportsをご覧ください。

predefined_reports.png

既知の制約

XOpsセキュリティ検出レポートでは、サイトまたはSDPユーザーによるフィルタリングをサポートしていません。 フィルターが設定されている場合、それらはレポートには反映されず、すべてのサイトとSDPユーザーのデータを表示します。

定期的なXOpsセキュリティ検出レポートの作成

Create a new recurring report by defining the Filters for the items included in the report, as well as the Schedule which defines how often the report is generated - every two minutes, daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Schedule also defines the time range that is covered by each report.

You can select a mailing list of email addresses for the recipients, which can include Cato Management Application admins, and external users.

For more information about Mailing Lists, see Working with Mailing Lists.

To create a recurring report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, find and select the template you want to use to generate the report.

  3. Click Generate > Create Schedule.

  4. Enter a Report Name.

  5. (Optional) In Filters, select specific sites or users for the predefined report.

    By default, the predefined report includes all sites and users.

  6. Define when the report will be generated and sent:

    1. Select the Frequency.

    2. For Weekly and Monthly scheduled reports, in Every select the day that the report is sent.

    3. Select the timezone.

  7. Select the export format: PDF or CSV.

  8. In Subscriptions, select the Mailing List that receives the report.

    You can click New to create a new mailing list.

  9. Click Save Schedule. The report is added to the Saved Reports tab.

Generating a Recurring Report On Demand

Recurring reports are automatically generated based on their schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a recurring report on demand, in which case the generated report uses the defined time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the recurring report. For more information about the time range of recurring reports, see Cato Reports.

To generate a recurring report on demand:

  1. From the navigation pane, select Home > Reports.

  2. From the Saved Reports tab, find the recurring report and click Generate Now.

  3. From the Generated PDFs tab, find the report and click Download.

一度限りのXOpsセキュリティ検出レポートの作成

XOpsセキュリティ検出テンプレートに基づいて、一回限りのレポートを作成できます。 レポートに含まれる項目のためのフィルターを定義します。

To create a one-time report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, select the template you want to use to generate the report.

  3. Select Generate > Generate Now.

  4. Enter a Report Name.

  5. Define the relevant Filters for your report.
    These are specific to the report type.

  6. Define the Timeframe and Timezone of the report.

  7. Select the Format: PDF or CSV.

  8. Click Generate.
    The report is generated, and you can download it from the Generated tab.

XOpsセキュリティ検出レポートの理解

これらはXOpsセキュリティ検出レポートのセクションです:

  • エグゼクティブ概要

    • 選択された期間におけるイベントとストーリーの全体的な合計、含まれるもの:

      • すべてのイベント:アカウントのためのイベントの総数

      • セキュリティイベント:アカウントに対して有効化されたCatoセキュリティエンジンから生成されたイベントの数

      • 作成されたストーリー:アカウントのために生成されたXOpsストーリーの総数

      • 高い重大度のストーリー:重大度が7-10の間で作成されたストーリーの数

  • 重大度ごとに作成されたストーリー:アカウントのために生成されたストーリーの重大度ごとの内訳

    • 高 - 重大度が7-10のストーリー

    • 中 - 重大度が4-6のストーリー

    • 低 - 重大度が1-3のストーリー

  • サイトごとに作成されたストーリー:ストーリーを生成したトラフィックを持つサイトごとのストーリーの数

  • 重大度ごとの時間ごとに作成されたストーリー:作成されたストーリーの数を示すグラフで重大度ごとの内訳を含みます。 このグラフは6か月間のデータを示しています

  • トップ5 MITRE手法:アカウントのために作成されたストーリーにおけるトップMITRE ATT&CK®手法。 MITRE ATT&CK®フレームワークについて詳しくは、MITRE ATT&CK® ダッシュボードを使用するを参照してください

  • トップ5攻撃の兆候:アカウントのために作成されたストーリーにおけるトップ攻撃の兆候。 攻撃の兆候について詳しくは、インディケーションカタログを使用するを参照してください

  • エンジンタイプごとに作成されたストーリー:アカウントのために生成されたストーリーのエンジンタイプごとの内訳。 異なるXOpsエンジンについて詳しくは、インディケーションカタログを使用するをご覧ください

  • 場所ごとに作成されたストーリー:アカウントのストーリーで検出された脅威に関連する国別の上位10の場所。 脅威の位置には、ストーリーの中のターゲットとソースの位置が含まれます。 したがって、単一のストーリーは複数の脅威の位置に関連付けられます。

  • 一般的なセキュリティ姿勢

    • トップブロックアプリケーションインターネットファイアウォール:インターネットファイアウォールでブロックされたトップアプリケーションとヒット数

    • トップブロックカテゴリインターネットファイアウォール:インターネットファイアウォールでブロックされたトップカテゴリとヒット数

    • トップブロックアプリケーションWANファイアウォール:WANファイアウォールでブロックされたトップアプリケーションとヒット数

    • トップブロックカテゴリWANファイアウォール:WANファイアウォールでブロックされたトップカテゴリとヒット数

    • リスクレベルごとのIPSイベント:リスクレベルごとのIPSブロックイベントの内訳を示すチャート

    • アンチマルウェアブロックイベントレポートの期間内に発生したマルウェア対策サービスのすべてのブロックイベントを示すグラフ

  • ストーリーが作成されました

    このセクションでは、レポートの期間中に作成されたすべてのXOpsストーリーを素早く確認することができます。

    これらはテーブル列です:

    • ストーリーへのリンク:ストーリーワークベンチでストーリーのドリルダウンページを開くためにクリック

    • 作成日:ストーリーが作成された日付

    • ストーリー期間:ストーリーの最初のトラフィックフローからそのストーリーが閉じられるまで、またはレポートが生成されるまでの経過時間

    • インジケーション:ストーリーの攻撃の兆候 インジケーションについて詳しくは、「インディケーションカタログを使用する」を参照してください

    • タイプ:ストーリーを作成したXOpsエンジン。

    • ストーリーの重大度。

    • サイト:ネットワーク内のストーリーを生成したトラフィックを持つサイト。

    • ソース:ストーリーに関与したネットワーク上のIPアドレス、デバイス名、またはSDPユーザー

    • ステータス:レポートが生成された時点でのストーリー調査のステータス。 可能性のある値には、次のようなものがあります: 開、閉、詳細情報保留中 (保留中の日数を含む)